20.7 Dental Informatics, Electronic Records & Emerging Technology

Key Takeaways

  • The HIPAA Privacy Rule governs use and disclosure of protected health information, while the Security Rule requires administrative, physical, and technical safeguards for electronic protected health information
  • The minimum necessary standard limits use and disclosure to the least information needed, but it does not apply to disclosures for treatment purposes
  • Patients have a right to access and obtain a copy of their record, generally within 30 days and for a reasonable cost-based fee
  • A breach of unsecured protected health information requires notification to affected individuals and the Secretary of Health and Human Services, while encrypted data generally falls within safe harbor
  • Teledentistry expands access for triage, consultation, and monitoring, but the standard of care, licensure requirements, and consent obligations are unchanged
Last updated: August 2026

Dental Informatics, Electronic Records & Emerging Technology

Why this matters on the INBDE: FK10 — research methodology, analysis, and informatics tools — carries 10% of examination items, and its largest cell is against Practice and Profession. Records and information technology are also two named Clinical Content areas.

The Electronic Dental Record

A complete record, electronic or paper, contains: patient identification and contact information; medical and dental history with dated updates; examination findings; radiographs and images; diagnoses; the treatment plan with alternatives presented; informed consent discussions; every treatment rendered with materials, anesthetic type and quantity, and lot numbers where required; prescriptions; laboratory prescriptions; referrals and consultation responses; missed and cancelled appointments; and all patient communications.

Advantages of electronic records: legibility, integrated imaging, automated recall and clinical alerts, e-prescribing with drug-interaction checking, structured data enabling practice-level quality measurement, and remote accessibility.

Risks specific to electronic records:

  • Copy-forward error — carrying a prior note into today's entry so the record documents an examination that never happened.
  • Template-driven entries that record findings not actually observed.
  • Alert fatigue — clinicians dismiss warnings reflexively when too many fire.
  • Audit trails — every view and edit is logged. This protects the patient and also means that late or altered entries are visible, so never attempt to alter an entry to conceal an event. Use the amendment function.
  • Single point of failure — see the backup requirements in catastrophe preparedness.

HIPAA: Privacy, Security, and Breach Notification

The Privacy Rule

Governs the use and disclosure of protected health information (PHI) in any form.

ConceptRule
Permitted without authorizationTreatment, payment, and health care operations (TPO); disclosures required by law such as mandated abuse reporting, public health reporting, and certain law enforcement and judicial requests
Requires written authorizationMarketing, sale of PHI, most psychotherapy notes, and most other disclosures
Minimum necessary standardUse and disclose the least information needed for the purpose — but this standard does not apply to disclosures for treatment
Notice of Privacy PracticesMust be provided and, at the first service encounter, a good-faith effort made to obtain acknowledgment of receipt
Patient rightsAccess and a copy of the record (generally within 30 days, for a reasonable cost-based fee); request amendment; accounting of certain disclosures; request restrictions; request confidential communications; right to restrict disclosure to a health plan when the patient pays out of pocket in full
Business associate agreementsRequired with vendors that create, receive, maintain, or transmit PHI on the practice's behalf — billing services, IT support, cloud storage, laboratories that receive PHI

Incidental disclosures — a name overheard at the front desk — are permitted if reasonable safeguards are in place. The practical safeguards are quiet reception conversations, angled monitors and automatic screen locks, charts not left face-up, and a private area for financial and clinical discussions.

The Security Rule

Applies specifically to electronic PHI and requires three categories of safeguards:

  1. Administrative — a documented risk analysis, a risk management plan, assigned security responsibility, workforce training, sanction policy, and a contingency plan (data backup, disaster recovery, emergency mode operation).
  2. Physical — facility access controls, workstation security and positioning, and device and media controls including secure disposal and reuse.
  3. Technical — unique user identification, automatic logoff, access controls, audit controls, integrity controls, transmission security, and encryption.

Breach notification

A breach of unsecured PHI requires notification to affected individuals without unreasonable delay and no later than 60 days, to the Secretary of Health and Human Services (immediately for breaches affecting 500 or more individuals; annually for smaller breaches), and to prominent media for breaches affecting 500 or more residents of a state or jurisdiction.

Encryption is the practical safe harbor. A lost laptop or backup drive containing properly encrypted PHI generally does not constitute a breach of unsecured PHI; the same device unencrypted does, along with all the notification obligations that follow.

Ransomware involving PHI is presumed to be a breach unless a risk assessment demonstrates a low probability that PHI was compromised.

Teledentistry

Teledentistry is a delivery modality, not a different standard of care.

ModeDescriptionTypical dental use
SynchronousReal-time audio-videoConsultation, triage, post-operative check
Asynchronous (store-and-forward)Images and records transmitted for later reviewSpecialist review of radiographs and photographs
Remote patient monitoringData collected and transmitted over timeOrthodontic progress monitoring
Mobile healthApps and messagingHygiene reinforcement, appointment adherence

Obligations that do not change: the dentist must generally be licensed in the state where the patient is located; informed consent must include the limitations of a remote examination; documentation standards are identical; privacy and security requirements apply to the platform used; and prescribing rules, including controlled substance restrictions, still apply. Teledentistry expands access — especially for rural populations, long-term care residents, and school-based programs — but it cannot substitute for an examination when one is required to reach a diagnosis.

Digital Clinical Technology

TechnologyValueLimitation to communicate
Digital radiographySubstantial dose reduction, instant image, enhancement and sharingImage manipulation must preserve the original; do not enhance an image to create a finding
Cone beam CTUndistorted three-dimensional anatomyHigher dose; obligation to interpret the entire volume
Intraoral scanningNo impression material, immediate review, digital archivingLearning curve; deep subgingival margins remain difficult to capture
CAD/CAMSame-day restorations, consistent millingMaterial limitations; occlusal design still requires clinical judgment
Caries detection devices (transillumination, fluorescence)Adjunct sensitivity for occlusal lesionsFalse positives from stain and hypomineralization; never treat on a device reading alone
Electronic apex locatorsAccurate working length with less radiationConfirm with a radiograph in difficult anatomy
Artificial intelligence image analysisAssists in caries and bone-level detection, workflow triageAdjunct, not a diagnosis. The dentist remains responsible; training-data bias and false positives are real; regulatory clearance status matters

Evaluating Emerging Technology

Before adopting anything new, ask:

  1. What clinical question does it answer better than the current method?
  2. What is the evidence? Peer-reviewed clinical outcome data, not a manufacturer's brochure or an opinion leader's lecture.
  3. Is it cleared or approved by the appropriate regulator for the use you intend?
  4. What is the learning curve, and what is the outcome during it?
  5. What are the failure modes, and can they be detected?
  6. What does it cost in equipment, materials, training, maintenance, and chair time — and does the benefit justify it for this patient population?
  7. What must the patient be told? Using a novel technique or material is a material fact in informed consent, and the patient is entitled to know that an established alternative exists.

The ethical anchor: enthusiasm for a new technology does not lower the evidentiary bar. A dentist who adopts an unproven technique and does not disclose its novel status has failed both the duty of competence and the duty of veracity.

Test Your Knowledge

A dentist refers a patient to an oral surgeon and sends the complete medical history and radiographs. Does the minimum necessary standard limit this disclosure?

A
B
C
D
Test Your Knowledge

An unencrypted practice laptop containing 800 patients' records is stolen. Which notification obligations apply?

A
B
C
D
Test Your Knowledge

An artificial intelligence tool flags a suspected interproximal lesion on a bitewing that the dentist does not identify clinically or radiographically. What is the appropriate response?

A
B
C
D
Test Your Knowledge

A dentist licensed in State A wishes to provide a synchronous teledentistry consultation to a patient physically located in State B. What is the primary licensure consideration?

A
B
C
D